AI governance · risk & control matrix · live

The workflow that shows its working.

An invoice-to-pay process run by AI agents, where every step carries its risk lifecycle: the inherent risk before any control, the controls in place (typed, with design and operating effectiveness), and the residual risk after, judged against appetite. Then switch to Audit mode and run an IIA-style engagement over the same workflow: walkthrough, control testing, a finding, follow-up. Methodology cited to COSO/Deloitte, the IIA 2024 Global Internal Audit Standards, and KPMG publications, see the methodology panel below.

Synthetic process · illustrative ratings

8
risks assessed · 5×5 scales
15
controls · 4 IIA types
·
transactions run
·
audit finding

Process P-01 · Invoice-to-Pay

click a step for its risk lifecycle · S2 expands to its contained sub-process

Step

Risk heat map, inherent → residual

5×5 · impact-weighted appetite bands
AI Control Ledger, agents and humans, uniquely identifiedawaiting run
·Run the workflow to populate the ledger. Every agent and human action appends here, hash-chained.
Append-only · hash-chained · replayable. Unique identifiers on agents AND humans, per KPMG's agentic-AI control considerations #5-6.
Methodology, what's cited, what's convention, what's our extension
↓ Download as n8n workflow (JSON) the n8n export is the orchestration skeleton, importable as-is, the governance overlay is this page

risk before → typed controls → residual after → audit over the top · deterministic engine, seeded run, identical results every time · willytai.com